Cybertrion Systems

[2/5] Websense User-Agent Filtering Bypass Security Issue

December 13th, 2007 by
[2/5] Websense User-Agent Filtering Bypass Security Issue

:mrhinkydink has reported a security issue in Websense, which can be exploited by malicious people to bypass certain security restrictions.The security issue is caused due to the improper filtering of certain HTTP requests. This can be exploited to bypass URL filtering rules and gain access to restricted websites via specially crafted User-Agent fields in outgoing HTTP headers.The security issue is reported in version 6.3.1. Prior versions may also be affected.Solution:The vendor issued automatic updates that corrected the security issue.Provided and/or discovered by:mrhinkydinkOriginal Advisory:mrhinkydink:http://mrhinkydink.blogspot.com/2007/12/websense-policy-filtering-bypass.htmlWebsense:http://www.websense.com/SupportPortal/SupportKbs/976.aspx

Original post by pooja

[2/5] Websense User-Agent Filtering Bypass Security Issue

Related Articles:
  • [2/5] Websense “username” Cross-Site Scripting Vulnerability
  • [2/5] NuFW Time Based Filtering Rules Security Bypass
  • [2/5] Cisco Trust Agent “User Notification” Authentication Bypass
  • [3/5] Cisco Security Agent Unspecified System Driver Buffer Overflow Vulnerability
  • [4/5] Sarg User-Agent Processing Multiple Vulnerabilities


  • Posted in Advisories - Exploits | | [2/5] Websense User-Agent Filtering Bypass Security Issue

    << [2/5] JBoss Seam “order” EJBQL Injection Vulnerability | [4/5] Fastpublish CMS designconfig.php File Inclusion >>